I don't think it's your computer joining the network that's the issue; the network itself is likely tainted. By extreme example, a rogue cell tower was demonstrated last year which monitored outgoing SMS messages. Your phone would automatically join it because its signal strength was greater and it had all required information.
The issue with Defcon Wi-Fi is that you should assume all outbound traffic is captured. Are you sure your mail notifier, Dropbox client, IM client, etc, aren't sending credentials or some kind that can be (at least temporarily) exploited?
You make the mistake of assuming that all networks are created equal and that just because you could potentially be vulnerable on a network that this vulnerability would have manifest itself to you by now.
For example, signin for this very website is done in cleartext. Do you have "big problems" right now? No, I hardly expect you do. Would you expect to if you jumped onto your standard open coffeeshop wifi? Realisticly no. It is fairly unlikely that anyone in your average starbucks gives half a shit about your HNs account.
Now, if you went to DEFCON and didn't take additional precautions? Well, I'm not going to say anyone will really happen to care about your account even then, but you can be damned sure they'll log it anyway.
My point is 1) "any other network" on average is probably not as hostile as the open networks as DEFCON, and 2) your vulnerability will not necessarily manifest visibly as "big problems".
Comments
I don't think it's your computer joining the network that's the issue; the network itself is likely tainted. By extreme example, a rogue cell tower was demonstrated last year which monitored outgoing SMS messages. Your phone would automatically join it because its signal strength was greater and it had all required information.
The issue with Defcon Wi-Fi is that you should assume all outbound traffic is captured. Are you sure your mail notifier, Dropbox client, IM client, etc, aren't sending credentials or some kind that can be (at least temporarily) exploited?
yes. i'd have big problems on any other network i'd join if i wasn't sure, wouldn't i?
You make the mistake of assuming that all networks are created equal and that just because you could potentially be vulnerable on a network that this vulnerability would have manifest itself to you by now.
For example, signin for this very website is done in cleartext. Do you have "big problems" right now? No, I hardly expect you do. Would you expect to if you jumped onto your standard open coffeeshop wifi? Realisticly no. It is fairly unlikely that anyone in your average starbucks gives half a shit about your HNs account.
Now, if you went to DEFCON and didn't take additional precautions? Well, I'm not going to say anyone will really happen to care about your account even then, but you can be damned sure they'll log it anyway.
My point is 1) "any other network" on average is probably not as hostile as the open networks as DEFCON, and 2) your vulnerability will not necessarily manifest visibly as "big problems".
being 100% sure is 100% impossible
are you sure?
evidently he isn't
This is why I tend to leave the laptop & cell behind when attending DEF CON. Besides, it's about meeting the people there, isn't it?